<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE BYOD: certificate generation failed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547074#M496728</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looking at your Android screenshot again, it says the certificate is only valid for 1.1.1.1. Although no longer a recommended value for WLC virtual interface, 1.1.1.1 is likely what your WLC has for its virtual interface. If so, then it's an indication that the WLC ACL is not allowing the connection to play.google.com and that the WLC is enabled for HTTPS redirection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is not helping, please engage Cisco TAC to troubleshoot further.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 30 Jun 2018 13:45:39 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-06-30T13:45:39Z</dc:date>
    <item>
      <title>ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547062#M496716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;I followed the directions stated on the Youtube link "&lt;A href="https://www.youtube.com/watch?v=z0sRiffVdpg" title="https://www.youtube.com/watch?v=z0sRiffVdpg"&gt;ISE 2.2 Android Provisioning with EST Authentication (Certificate Generation Failed) - YouTube&lt;/A&gt;" but despite the mentioned configuration, again I get the same "&lt;STRONG&gt;Certificate Generation Failed&lt;/STRONG&gt;" message during BYOD onboarding with single-SSID on my test Android 7.0 device. Also I'm using ISE 2.4 patch 1.&lt;/P&gt;&lt;P&gt;AS seen I've created a new condition and used it in a new Authz rule and put it before other rules. But I got no match hint and the same error message was and is still there!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="117836" alt="ise7.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117836_ise7.png" style="height: 455px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a firewall between clients and ISE server, but permitted all traffic from those clients destined everywhere; So it could not be considered a firewall-related issue. &lt;/P&gt;&lt;P&gt;How can I fix this? And I don't understand why this is necessary? I've not seen such recommendation or configuration on regular admin guides, videos or even on Cisco press books!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advanced.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 10:47:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547062#M496716</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-06-26T10:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547063#M496717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hossein, are you using EST as opposed to SCEP? If not, the suggestions in the video is irrelevant. I suggest configuring basic BYOD using the wireless setup wizard and make sure it works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 23:37:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547063#M496717</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-06-26T23:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547064#M496718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;Hi;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;No I configured SCEP in my lab. I hadn't heard anything about EST till this week. Actually I followed BYOD instructions stated on Cisco Community and double checked it with ISE Admin Guide and Cisco Press&amp;nbsp; BYOD (2nd edition) book.If EST is irrelevant while SCEP is configured, then it would called normal if I hadn't heard anything about it in official guides. &lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Do you have any idea of what would be the reason behind error "Certificate Generation Failed"?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 06:07:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547064#M496718</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-06-27T06:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547065#M496719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I delete the NSA from the Android device but after being redirected to the BYOD portal and clicking on the icon to download NSA app from Google Play, a message pops up asking me to login again to that SSID, which takes me to the first page of the BYOD portal and this loops continues. I get this error on the Android browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screenshot_20180627-131909.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117845_Screenshot_20180627-131909.png" style="height: 1102px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested it with other browsers but got the same type of error regarding SSL certificate of the webpage. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 11:09:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547065#M496719</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-06-27T11:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547066#M496720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That’s because you’re not using a valid certificate that the endpoints know about&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you’re a Cisco partner would recommend using our dCloud setup our Deploying ISE POV kit to understand how it works with proper setup as these come with a well known certificate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 12:11:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547066#M496720</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-06-27T12:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547067#M496721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So it's impossible to use Internal CA (without purchasing from a public well-known CA) along with BYOD. Did I get that right? &lt;/P&gt;&lt;P&gt;I checked the BYOD on my iPAD but it was unsuccessful too! I get redirected to the BYOD portal on ISE, but despite that I click on Trust and it shows the name of the certificate (as shown on the image), downloading the certificate fails. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="IMG_0111.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117846_IMG_0111.PNG" style="height: 827px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really got stuck. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 15:20:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547067#M496721</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-06-27T15:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547068#M496722</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please follow the instruction here to trust the ISE certificate:&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.apple.com/en-us/HT204477" title="https://support.apple.com/en-us/HT204477"&gt;Trust manually installed certificate profiles in iOS - Apple Support&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 15:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547068#M496722</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-06-27T15:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547069#M496723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;The problem is I cannot download the certificate at the first place (The displayed certificate on the image above "&lt;STRONG&gt;TLABSERVER-CA.cer&lt;/STRONG&gt;" is my internal Root CA certificate that includes my root ca public key), so there is no any certificate listed on the General &amp;gt; About &amp;gt; Certificate Trust Settings page. It shows only the first line which is "Trust Store Version" on that page. When I touch Download Now link at the image above, it says "Download Failed".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="117847" alt="ise8.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117847_ise8.png" style="height: 528px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This image shows Administration &amp;gt; System &amp;gt; Certificates &amp;gt; Certificate Authority &amp;gt; External CA settings page on ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 06:16:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547069#M496723</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-06-28T06:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547070#M496724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like you are doing SCEP to external CA, is that what you are trying to do? If so have you configured MS CA to work with ISE? If this is not your intent or just to make sure onboarding is working, I suggest just leveraging internal CA instead.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 22:22:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547070#M496724</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-06-28T22:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547071#M496725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi. &lt;/P&gt;&lt;P&gt;Yes I'm using SCEP and configured MS ADCS exactly as stated on the various Cisco Community documents created for BYOD. I used these documents:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-68160"&gt;How To: ISE &amp;amp;amp; BYOD: Onboarding, Registering &amp;amp;amp; Provisioning&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-68159"&gt;How To: ISE &amp;amp;amp; BYOD: Using Certificates For Differentiated Access&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The certificate template is created on ADCS server based on these Cisco guides. I double-checked the configs but it seems there is no difference between what I did and the docs. You can take a look at the configs by clicking on this link, if you want. &lt;A href="https://1drv.ms/u/s!AtnSgqfSTcPBgYZJcYdKJApOoy_DsQ" title="https://1drv.ms/u/s!AtnSgqfSTcPBgYZJcYdKJApOoy_DsQ"&gt;https://1drv.ms/u/s!AtnSgqfSTcPBgYZJcYdKJApOoy_DsQ&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ISE 2.4 patch 1&lt;/LI&gt;&lt;LI&gt;2 Windows server 2012 R2 computer (one as ADDC and another one as ADCS, which is not member of the internal domain)&lt;/LI&gt;&lt;LI&gt;Cisco WLC 2504 software version 8.0.121.0&lt;/LI&gt;&lt;LI&gt;Android 7.0&lt;/LI&gt;&lt;LI&gt;iOS 11.0&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jun 2018 06:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547071#M496725</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-06-29T06:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547072#M496726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On this Apple iPad, you are using FireFox app instead of the regular mobile Safari. Firefox is not opening the certificate, even if it downloaded, and installing it under Settings &amp;gt; General &amp;gt; Profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, ensure that the ACL is properly allowing access to the ISE PSN. And, then use Apple iOS mobile Safari, instead of Firefox app.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jun 2018 20:05:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547072#M496726</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-29T20:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547073#M496727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The fact that the connection is untrusted to Google play store appears either due to the connection not permitted by your ACL or intercepted by a web proxy server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jun 2018 20:10:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547073#M496727</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-29T20:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547074#M496728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looking at your Android screenshot again, it says the certificate is only valid for 1.1.1.1. Although no longer a recommended value for WLC virtual interface, 1.1.1.1 is likely what your WLC has for its virtual interface. If so, then it's an indication that the WLC ACL is not allowing the connection to play.google.com and that the WLC is enabled for HTTPS redirection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is not helping, please engage Cisco TAC to troubleshoot further.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 Jun 2018 13:45:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547074#M496728</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-30T13:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547075#M496729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have 2 different ACLs on WLC, one for Android and one for iOS. (My ISE IP address is 10.1.204.168).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="118070" alt="wlc3.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/118070_wlc3.png" style="height: 281px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only difference between 2 of them is URLs. Based on the docs I enabled HTTPS redirect on WLC. Shouldn't it be that way?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 Jun 2018 15:58:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547075#M496729</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-06-30T15:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547076#M496730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The thing with Android ACL is that it keeps changing. I do not think your DNS ACL really working. Unfortunately, the one worked in our alpha network 1.5 years ago is no longer working to access Android Play store.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be easier to restrict the internal network access but to allow Internet or use a separate network to download the Cisco NSW app from the store.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an ACL to restrict internal access from one of our test setups, where the internal network is 10.0.0.0/8, DNS is 10.1.100.10, and ISE 10.1.100.21:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'andale mono', times;"&gt;(Cisco Controller) &amp;gt;show acl detailed PERMIT-Internet&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'andale mono', times;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source Port&amp;nbsp; Dest Port&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'andale mono', times; font-size: 8pt;"&gt;Index&amp;nbsp; Dir&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address/Netmask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address/Netmask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Prot&amp;nbsp;&amp;nbsp;&amp;nbsp; Range&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Range&amp;nbsp;&amp;nbsp;&amp;nbsp; DSCP&amp;nbsp; Action&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Counter&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'andale mono', times;"&gt;------ --- ------------------------------- ------------------------------- ---- ----------- ----------- ----- ------- -----------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'andale mono', times;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; In&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.1.100.10/255.255.255.255&amp;nbsp; 17&amp;nbsp;&amp;nbsp;&amp;nbsp; 0-65535&amp;nbsp;&amp;nbsp;&amp;nbsp; 53-53&amp;nbsp;&amp;nbsp;&amp;nbsp; Any Permit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 207&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'andale mono', times;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp; In&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.1.100.21/255.255.255.255&amp;nbsp; Any&amp;nbsp;&amp;nbsp; 0-65535&amp;nbsp;&amp;nbsp;&amp;nbsp; 0-65535&amp;nbsp; Any Permit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1586&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'andale mono', times;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&amp;nbsp; In&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp; 0-65535&amp;nbsp;&amp;nbsp;&amp;nbsp; 0-65535&amp;nbsp; Any Permit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'andale mono', times;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp; In&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.0/255.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Any&amp;nbsp;&amp;nbsp; 0-65535&amp;nbsp;&amp;nbsp;&amp;nbsp; 0-65535&amp;nbsp; Any&amp;nbsp; Deny&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 43&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'andale mono', times;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 Any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Any&amp;nbsp;&amp;nbsp; 0-65535&amp;nbsp;&amp;nbsp;&amp;nbsp; 0-65535&amp;nbsp; Any Permit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 34780&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Jul 2018 00:09:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547076#M496730</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-01T00:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547077#M496731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Following Hosuk's &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-69430"&gt;Using DNS-Based ACL for Chromebooks and Android Devices&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt;, it's working for my Nexus 5X/Android 8.1 on a WLC 5520 running AireOS 8.5.131.0 and AP 2702i.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Earlier it was not working on vWLC running 8.0.120.0, due to CSCus61445.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Jul 2018 02:44:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547077#M496731</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-01T02:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547078#M496732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I pinged the various Google sites and created ACL entries on the WLC with those IP addresses and again it didn't work. &lt;/P&gt;&lt;P&gt;I tested on my iPAD, this time with Safari browser instead of Firefox, and this time I redirected a little further. It asked me to install a profile and after I accept the prompt, it installed the root CA, but it asked me to install the profile second time, but at this point I got an error message like this. &lt;/P&gt;&lt;P&gt;&lt;IMG alt="IMG_0118.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/118139_IMG_0118.PNG" style="height: 465px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can see that my root CA certificate has been verified at the first step. but the 2nd step failed. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 10:47:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547078#M496732</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-07-04T10:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547079#M496733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since your domain is .local, I believe either your root CA is a private enterprise PKI or the server certificate is self-signed. In that case, please read how to &lt;A href="https://support.apple.com/en-us/HT204477"&gt;Trust manually installed certificate profiles in iOS - Apple Support&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 15:57:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547079#M496733</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-04T15:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547080#M496734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For Google Android, I would suggest you to try the ACL &lt;SPAN style="color: #3d3d3d; font-family: 'andale mono', times; font-size: 10.666666984558105px;"&gt;PERMIT-Internet&lt;/SPAN&gt; that I posted in comment 14. Or, get the NSW app first using another WLAN or some other means.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 19:10:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547080#M496734</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-04T19:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE BYOD: certificate generation failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547081#M496735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just worked with someone who had .local and apple doesn’t like that even if you manually install cert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You Will need to move away from using the TLD of .local&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 22:16:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-certificate-generation-failed/m-p/3547081#M496735</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-07-04T22:16:11Z</dc:date>
    </item>
  </channel>
</rss>

